Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown
CVE-2023-6691
Disclosure Date: December 18, 2023 (last updated December 29, 2023)
Cambium ePMP Force 300-25 version 4.7.0.1 is vulnerable to a code injection vulnerability that could allow an attacker to perform remote code execution and gain root privileges.
0
Attacker Value
Unknown
CVE-2022-24802
Disclosure Date: April 01, 2022 (last updated February 23, 2025)
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-25010
Disclosure Date: March 01, 2022 (last updated February 23, 2025)
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
0
Attacker Value
Unknown
CVE-2021-23417
Disclosure Date: July 28, 2021 (last updated February 23, 2025)
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
0
Attacker Value
Unknown
CVE-2020-20412
Disclosure Date: December 26, 2020 (last updated February 22, 2025)
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
0
Attacker Value
Unknown
CVE-2019-17445
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
0
Attacker Value
Unknown
CVE-2017-5258
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string can provide a URL for a configuration file over SNMP with XSS strings in certain SNMP OIDs, serve it via HTTP, and the affected device will perform a configuration restore using the attacker's supplied config file, including the inserted XSS strings.
0
Attacker Value
Unknown
CVE-2017-5256
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.
0
Attacker Value
Unknown
CVE-2017-5257
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW) community string can insert XSS strings in certain SNMP OIDs which will execute in the context of the currently-logged on user.
0
Attacker Value
Unknown
CVE-2017-5254
Disclosure Date: December 20, 2017 (last updated November 26, 2024)
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the capability of changing passwords for other accounts, including admin, after disabling a client-side protection mechanism.
0